管理 HA 组

高可用性

 

 

无论将 FortiGate 设备配置为主动 - 主动模式 HA 或者主动 - 被动模式 HA,网络设 备连接和下面的操作步骤都完全相同。

以下操作用于把 FortiGate 连接到您的网络上:

1 将每一台 FortiGate 的内部网络接口都连接到一个与您的内部网络相连的交换机或者

集线器上。

2 将每一台 FortiGate 的外部网络接口都连接到一个与您外部网络相连的交换机或者集

线器上。

3 可以选择将 FortiGate 的 DMZ 接口连接到 DMZ 网络的交换机或者集线器上。

4 可以选择将 FortiGate 的接口 1 到 8 连接到其它网络的交换机或者集线器上。

5 把 FortiGates 的 HA 接口连接到一台单独的交换机或者集线器上。 当您连接了 HA 簇之后,可以进行 启动 HA 簇操作。

启动 HA

将 HA 簇中的全部 FortiGate 设备都配置为 HA 并且将这个簇连接起来之后,可以使 用以下操作启动 HA 簇。

1 为簇中的所有 HA 设备加电。

在设备启动过程中,它们将协商以选出主簇设备和附属设备。这个协商过程是自动进 行的,无须用户干预。

当协商完成后,这个簇已经准备好处理网络通讯了,您可以使用 第 68 页 管理 HA 组中的信息在这个簇登录和进行管理。

管理 HA 组

当 FortiGate 设备启动并运行时,您可以把它作为一个簇进行管理,而不是管理一 组独立的 FortiGate 设备。对 HA 簇的管理 , 可以通过将基于 Web 的管理程序或者 CLI 连接到为管理访问配置好的任何接口来实现。因为这个簇中的全部设备都配置了相同 的接口 IP 地址 (除了 HA 接口),连接到 IP 地址配置为管理访问连接的任意接口都将 自动将连接转到主 FortiGate 设备。

您还可以通过连接到簇中的单独设备的 HA 接口 (每个接口配置了不同的 IP 地址) 来对它们进行管理。

您也可以通过连接到主设备的 CLI 来管理单独的设备。从这里可以使用命令 execute ha manage 连接到簇中的每个设备的 CLI。

本节描述了以下内容:

·查看 HA 簇成员状态 ·监视簇成员 ·监视簇会话 ·查看和管理簇日志消息 ·单独管理簇中的设备 ·同步簇配置 ·返回到独立模式配置 ·在失效恢复后替换 FortiGate

68

美国飞塔有限公司

Page 80
Image 80
Fortinet 500 manual 管理 Ha 组, 启动 Ha 簇

500 specifications

Fortinet 500 is a next-generation firewall (NGFW) that is part of Fortinet's acclaimed FortiGate family, designed to provide advanced security for medium to large enterprises. This appliance is known for its high performance, flexibility, and ability to protect networks from a variety of cyber threats through its robust features and technologies.

One of the main features of the Fortinet 500 is its integrated security capabilities. It combines multiple security functions into a single device, allowing organizations to manage everything from intrusion prevention and antivirus to web filtering and application control. This integration leads to simplified management and increased efficiency, as users can address multiple security needs without deploying multiple devices.

The Fortinet 500 runs on the FortiOS operating system, which is known for its simplicity and user-friendliness. FortiOS provides a centralized management interface that allows for the easy configuration and monitoring of security policies across the entire network. Additionally, the Fortinet management tools, such as FortiManager and FortiAnalyzer, enable detailed insights and reporting capabilities, helping organizations stay compliant with their security mandates.

Another characteristic that sets Fortinet 500 apart is its advanced threat intelligence, powered by the FortiGuard Labs. This global threat intelligence system continuously updates the firewall with the latest threat signatures and attack vectors, ensuring that organizations stay ahead of emerging threats. The firewall also employs machine learning and artificial intelligence to detect and mitigate sophisticated attacks in real-time.

Performance is crucial in any security appliance, and the Fortinet 500 does not disappoint. With hardware acceleration and purpose-built security processors, it delivers high throughput levels, enabling organizations to maintain productivity without sacrificing security. This level of performance is particularly beneficial in environments with heavy traffic and bandwidth demands.

In addition to these core features, the Fortinet 500 supports seamless integration with other security solutions within the Fortinet Security Fabric. This comprehensive approach allows for greater visibility and control over the entire security posture of an organization.

Overall, the Fortinet 500 is a powerful NGFW that offers a blend of advanced security features, ease of management, top-notch performance, and robust threat intelligence. Its ability to adapt to the ever-evolving landscape of cybersecurity makes it a valuable asset for businesses seeking to safeguard their digital assets and ensure seamless network operation.